.. / CVE-2020-17505

Exploit for Artica Web Proxy 4.30 - OS Command Injection (CVE-2020-17505)

Description:

Artica Web Proxy 4.30 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

Nuclei Template

View the template here CVE-2020-17505.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-17505.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-17505
https://blog.max0x4141.com/post/artica_proxy/
https://github.com/ARPSyndicate/kenzer-templates
http://packetstormsecurity.com/files/159267/Artica-Proxy-4.30.000000-Authentication-Bypass-Command-Injection.html
https://github.com/sobinge/nuclei-templates